[ 
https://issues.apache.org/jira/browse/CAMEL-25229?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen resolved CAMEL-25229.
---------------------------------
    Resolution: Fixed

Merged via https://github.com/apache/camel/pull/27255

> camel-hazelcast: serialization filter docs and WARN for user-supplied configs
> -----------------------------------------------------------------------------
>
>                 Key: CAMEL-25229
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25229
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-hazelcast
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> Follow-up to CAMEL-23414.
> Camel applies a default {{JavaSerializationFilterConfig}} (allow-list 
> {{java.}}, {{javax.}}, {{org.apache.camel.}}; deny-list {{java.net.}}) only 
> to the Hazelcast configurations it builds itself. A configuration supplied by 
> the user is used unchanged, by design:
> * a {{Config}} / {{ClientConfig}} bean passed as {{hazelcastConfig}}
> * a {{hazelcastConfigUri}}
> * a pre-built {{hazelcastInstance}}, or one looked up by 
> {{hazelcastInstanceName}}
> The Java serialization settings of such an instance are whatever the user's 
> configuration declares. Hazelcast's own default configurations 
> ({{hazelcast-default.xml}}, {{hazelcast-client-default.xml}}) declare no 
> {{<java-serialization-filter>}}, so a configuration based on them has no 
> filter unless the user adds one.
> Today this is described only in the 4.18 and 4.21 upgrade guides. The 
> camel-hazelcast component pages do not mention the serialization filter, and 
> nothing at runtime tells users that the configuration they supplied has none.
> h3. Proposed changes
> # *Documentation* 
> ({{components/camel-hazelcast/src/main/docs/hazelcast-summary.adoc}}): add a 
> section explaining which instances get Camel's default filter (the ones Camel 
> creates itself) and which do not (anything the user supplies). Show how to 
> declare a {{JavaSerializationFilterConfig}} that covers the application's own 
> classes, in XML and in Java, and mention the JVM-wide {{-Djdk.serialFilter}} 
> alternative.
> # *Runtime WARN* ({{HazelcastDefaultComponent#getOrCreateHzInstance}} and 
> {{#getOrCreateHzClientInstance}}): when Camel starts a member or client from 
> a user-supplied {{Config}} / {{ClientConfig}} (bean or 
> {{hazelcastConfigUri}}) whose {{SerializationConfig}} has no 
> {{JavaSerializationFilterConfig}}, log a WARN pointing to the new 
> documentation section. The user's configuration is not modified.
> # *Tests*: the WARN is logged for a user-supplied configuration without a 
> filter, and is not logged when one is declared.
> h3. Out of scope
> Applying Camel's default filter to user-supplied configurations. Every 
> application class outside the default allow-list would become unreadable, so 
> that change would need its own discussion and an upgrade-guide entry.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to